Product
medium
advisory
Detection of AWS SES Identity Verify-Use-Delete Abusive Pattern
1 rule 3 TTPsAdversaries with unauthorized access to AWS Simple Email Service (SES) credentials may verify an attacker-controlled identity, send phishing or spam emails, and promptly delete the identity to evade detection and attribution.
Simple Email Service +2
cloud
aws
ses
resource-development
defense-evasion
discovery
credential-abuse
1r
3t
updated
medium
advisory
AWS SES Identity Deletion
2 rules 1 TTPDetection of an AWS Simple Email Service (SES) identity deletion event, potentially indicating an adversary attempting to cover their tracks after malicious activity.
Simple Email Service
attack.stealth
attack.t1070
cloud
2r
1t